CVE-2023-52616 — Improper Input Validation in Linux
Severity
5.5MEDIUMNVD
OSV7.5OSV6.5
EPSS
0.0%
top 94.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18
Latest updateJun 26
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: lib/mpi - Fix unexpected pointer access in mpi_ec_init
When the mpi_ec_ctx structure is initialized, some fields are not
cleared, causing a crash when referencing the field when the
structure was released. Initially, this issue was ignored because
memory for mpi_ec_ctx is allocated with the __GFP_ZERO flag.
For example, this error will be triggered when calculating the
Za value for SM2 separately.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages5 packages
▶CVEListV5linux/linuxd58bb7e55a8a65894cc02f27c3e2bf9403e7c40f — 0c3687822259a7628c85cd21a3445cbe3c367165+6
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
16📋Vendor Advisories
15💬Community
1Bugzilla
▶